CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-24305

CVSS 9.3v3.1pub. 2026-01-22upd. 2026-02-03

Azure Entra ID Elevation of Privilege Vulnerability

🤖 AI Analysis
How it works

The vulnerability is classified as CWE-285 (Improper Authorization), which means improper verification of access permissions to resources or operations. An attacker can send an appropriately crafted network request to Microsoft Entra ID without needing to possess any credentials. As a result of an authorization error, the system may grant access or permissions exceeding the permitted scope.

Impact

An attacker can gain unauthorized access to protected resources or operations within Microsoft Entra ID, leading to high exposure of data confidentiality and limited integrity breach. The vulnerability has a scope beyond the source component (Scope: Changed), which means potential impact on related systems and resources.

Mitigation & patch

Apply patches available from the vendor according to references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24305. In the case of Microsoft cloud services, patches may be deployed automatically — it is recommended to verify the update status in the Microsoft Security Update Guide panel.

Who is affected

Microsoft Entra ID — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
  • Microsoft Entra Id

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-69851CRITICAL9.9same product

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileg...

CVE-2026-69836CRITICAL10.0same product

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a...

CVE-2026-42901CRITICAL10.0PL ✓same product

Błąd walidacji źródła w Microsoft Entra ID umożliwia privilege escalation

CVE-2026-33843CRITICAL9.1PL ✓same product

Obejście uwierzytelnienia w Microsoft Azure Active Directory B2C

CVE-2026-40379CRITICAL9.3PL ✓same product

Ujawnienie wrażliwych danych w Azure Entra ID umożliwiające spoofing